{"id":199,"date":"2026-02-11T16:38:40","date_gmt":"2026-02-11T15:38:40","guid":{"rendered":"https:\/\/helloblog.io\/bg\/kritichna-uiazvimost-proizvolno-kachvane-na-failove-wpvivid-backup\/"},"modified":"2026-02-11T16:38:40","modified_gmt":"2026-02-11T15:38:40","slug":"kritichna-uiazvimost-proizvolno-kachvane-na-failove-wpvivid-backup","status":"publish","type":"post","link":"https:\/\/helloblog.io\/bg\/kritichna-uiazvimost-proizvolno-kachvane-na-failove-wpvivid-backup\/","title":{"rendered":"\u041a\u0440\u0438\u0442\u0438\u0447\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442 \u0437\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u043d\u043e \u043a\u0430\u0447\u0432\u0430\u043d\u0435 \u043d\u0430 \u0444\u0430\u0439\u043b\u043e\u0432\u0435 \u0432 WPvivid Backup: \u043a\u043e\u0433\u0430 \u0440\u0435\u0430\u043b\u043d\u043e \u0442\u0435 \u0437\u0430\u0441\u044f\u0433\u0430 \u0438 \u043a\u0430\u043a\u0432\u043e \u0434\u0430 \u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0448"},"content":{"rendered":"\n<p>\u0421\u0435\u0440\u0438\u043e\u0437\u0435\u043d security advisory \u043e\u0442 Wordfence \u0437\u0430\u0441\u0435\u0433\u043d\u0430 \u043f\u043b\u044a\u0433\u0438\u043d\u0430 <strong>WPvivid Backup &#038; Migration<\/strong> (\u0432 Wordfence Intelligence \u0435 \u043e\u043f\u0438\u0441\u0430\u043d \u043a\u0430\u0442\u043e <em>Migration, Backup, Staging<\/em>), \u043a\u043e\u0439\u0442\u043e \u0438\u043c\u0430 \u043d\u0430\u0434 <strong>800,000 \u0430\u043a\u0442\u0438\u0432\u043d\u0438 \u0438\u043d\u0441\u0442\u0430\u043b\u0430\u0446\u0438\u0438<\/strong>. \u0421\u0442\u0430\u0432\u0430 \u0434\u0443\u043c\u0430 \u0437\u0430 <strong>Unauthenticated Arbitrary File Upload<\/strong> \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442, \u043a\u043e\u044f\u0442\u043e \u043f\u0440\u0438 \u0443\u0441\u043f\u0435\u0448\u043d\u0430 \u0435\u043a\u0441\u043f\u043b\u043e\u0430\u0442\u0430\u0446\u0438\u044f \u0432\u043e\u0434\u0438 \u0434\u043e <strong>Remote Code Execution (RCE)<\/strong> &#8211; \u043a\u043b\u0430\u0441\u0438\u0447\u0435\u0441\u043a\u0438 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u0439 \u0437\u0430 \u043f\u044a\u043b\u0435\u043d takeover \u043d\u0430 WordPress \u0441\u0430\u0439\u0442.<\/p>\n\n\n\n<p>\u0412\u0430\u0436\u043d\u0438\u044f\u0442 \u043d\u044e\u0430\u043d\u0441: \u043f\u043e \u0434\u0430\u043d\u043d\u0438\u0442\u0435 \u0432 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u044f\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0442\u0430 \u0435 <strong>\u043a\u0440\u0438\u0442\u0438\u0447\u043d\u043e \u0440\u0435\u043b\u0435\u0432\u0430\u043d\u0442\u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u043d\u043e \u0437\u0430 \u0441\u0430\u0439\u0442\u043e\u0432\u0435, \u043d\u0430 \u043a\u043e\u0438\u0442\u043e \u0435 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0430\u043d \u043a\u043b\u044e\u0447 \u0432 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438\u0442\u0435 \u043d\u0430 \u043f\u043b\u044a\u0433\u0438\u043d\u0430<\/strong>, \u0437\u0430 \u0434\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0442 <em>\u0434\u0440\u0443\u0433 \u0441\u0430\u0439\u0442 \u0434\u0430 \u0438\u0437\u043f\u0440\u0430\u0442\u0438 \u0431\u0435\u043a\u044a\u043f \u043a\u044a\u043c \u0442\u044f\u0445<\/em>. \u0422\u0430\u0437\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u043d\u043e\u0441\u0442 \u0435 <strong>\u0438\u0437\u043a\u043b\u044e\u0447\u0435\u043d\u0430 \u043f\u043e \u043f\u043e\u0434\u0440\u0430\u0437\u0431\u0438\u0440\u0430\u043d\u0435<\/strong>, \u0430 \u0432\u0430\u043b\u0438\u0434\u043d\u043e\u0441\u0442\u0442\u0430 \u043d\u0430 \u043a\u043b\u044e\u0447\u0430 \u043c\u043e\u0436\u0435 \u0434\u0430 \u0441\u0435 \u0437\u0430\u0434\u0430\u0434\u0435 <strong>\u0434\u043e \u043c\u0430\u043a\u0441\u0438\u043c\u0443\u043c 24 \u0447\u0430\u0441\u0430<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u041e\u0431\u043e\u0431\u0449\u0435\u043d\u0438\u0435 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0442\u0430 (CVE, \u0432\u0435\u0440\u0441\u0438\u0438, \u0440\u0438\u0441\u043a)<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442: <strong>Unauthenticated Arbitrary File Upload<\/strong> (\u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u043d\u043e \u043a\u0430\u0447\u0432\u0430\u043d\u0435 \u043d\u0430 \u0444\u0430\u0439\u043b\u043e\u0432\u0435 \u0431\u0435\u0437 \u0430\u0432\u0442\u0435\u043d\u0442\u0438\u043a\u0430\u0446\u0438\u044f)<\/li>\n\n\n<li>\u041e\u0446\u0435\u043d\u043a\u0430: <strong>CVSS 9.8 (Critical)<\/strong><\/li>\n\n\n<li>CVE: <strong>CVE-2026-1357<\/strong><\/li>\n\n\n<li>\u0417\u0430\u0441\u0435\u0433\u043d\u0430\u0442\u0438 \u0432\u0435\u0440\u0441\u0438\u0438: <strong><= 0.9.123<\/strong><\/li>\n\n\n<li>\u041f\u043e\u043f\u0440\u0430\u0432\u0435\u043d\u0430 \u0432\u0435\u0440\u0441\u0438\u044f: <strong>0.9.124<\/strong><\/li>\n\n\n<li>\u041a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\/slug: <strong>wpvivid-backuprestore<\/strong><\/li>\n\n\n<li>\u0412\u0435\u043a\u0442\u043e\u0440 \u043d\u0430 \u0430\u0442\u0430\u043a\u0430 (\u0441\u043f\u043e\u0440\u0435\u0434 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435\u0442\u043e): \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u044a\u0440 <strong><code>wpvivid_action=send_to_site<\/code><\/strong><\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u041a\u043e\u0433\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0442\u0430 \u0442\u0435 \u0437\u0430\u0441\u044f\u0433\u0430 \u0440\u0435\u0430\u043b\u043d\u043e<\/h2>\n\n\n\n<p>Wordfence \u0438\u0437\u0440\u0438\u0447\u043d\u043e \u043e\u0442\u0431\u0435\u043b\u044f\u0437\u0432\u0430\u0442, \u0447\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044a\u0442 \u0441\u0442\u0430\u0432\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u043d \u043f\u0440\u0438 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u0430 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f: \u043a\u043e\u0433\u0430\u0442\u043e \u0432 WPvivid \u0435 <strong>\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0430\u043d \u043a\u0440\u0430\u0442\u043a\u043e\u0441\u0440\u043e\u0447\u0435\u043d \u043a\u043b\u044e\u0447<\/strong> (token\/key) \u0437\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u0442\u0430, \u043a\u043e\u044f\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0432\u0430 \u0441\u0430\u0439\u0442\u044a\u0442 \u0442\u0438 \u0434\u0430 <strong>\u043f\u043e\u043b\u0443\u0447\u0430\u0432\u0430 \u0431\u0435\u043a\u044a\u043f \u043e\u0442 \u0434\u0440\u0443\u0433 \u0441\u0430\u0439\u0442<\/strong>. \u0410\u043a\u043e \u043d\u0435 \u0438\u0437\u043f\u043e\u043b\u0437\u0432\u0430\u0448 \u0442\u043e\u0437\u0438 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u0439 \u0438 \u043d\u0435 \u0441\u0438 \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u0430\u043b\/\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0430\u043b \u043a\u043b\u044e\u0447, \u0440\u0438\u0441\u043a\u044a\u0442 \u0435 \u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u043d\u043e \u043f\u043e-\u043d\u0438\u0441\u044a\u043a.<\/p>\n\n\n\n<div class=\"wp-block-group callout callout-warning is-style-warning is-layout-flow wp-block-group-is-layout-flow\" style=\"border-width:1px;border-radius:8px;padding-top:1rem;padding-right:1.5rem;padding-bottom:1rem;padding-left:1.5rem\">\n\n<h4 class=\"wp-block-heading callout-title\">\u041f\u0440\u043e\u0432\u0435\u0440\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438\u0442\u0435 \u043d\u0430 WPvivid<\/h4>\n\n\n<p>\u0410\u043a\u043e \u0438\u043c\u0430\u0448 \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u0430\u043d \u0440\u0435\u0436\u0438\u043c \u0437\u0430 \u043f\u043e\u043b\u0443\u0447\u0430\u0432\u0430\u043d\u0435 \u043d\u0430 \u0431\u0435\u043a\u044a\u043f \u043e\u0442 \u0434\u0440\u0443\u0433 \u0441\u0430\u0439\u0442 (\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0430\u043d \u043a\u043b\u044e\u0447), \u043f\u0440\u0438\u0435\u043c\u0438, \u0447\u0435 \u0441\u0430\u0439\u0442\u044a\u0442 \u0442\u0438 \u0435 \u0432 \u043d\u0430\u0439-\u0440\u0438\u0441\u043a\u043e\u0432\u0430\u0442\u0430 \u0433\u0440\u0443\u043f\u0430 \u0438 \u043e\u0431\u043d\u043e\u0432\u0438 \u0432\u0435\u0434\u043d\u0430\u0433\u0430 \u0434\u043e 0.9.124.<\/p>\n\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0438 \u0430\u0442\u0430\u043a\u0430\u0442\u0430: \u043a\u0430\u043a \u0435\u0434\u043d\u0430 \u0433\u0440\u0435\u0448\u043a\u0430 \u0432 \u043a\u0440\u0438\u043f\u0442\u0438\u0440\u0430\u043d\u0435\u0442\u043e \u043e\u0442\u0432\u0430\u0440\u044f \u043f\u044a\u0442 \u0437\u0430 \u043a\u0430\u0447\u0432\u0430\u043d\u0435 \u043d\u0430 PHP<\/h2>\n\n\n\n<p>\u0422\u0435\u0445\u043d\u0438\u0447\u0435\u0441\u043a\u0430\u0442\u0430 \u0447\u0430\u0441\u0442 \u0435 \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u0430, \u0437\u0430\u0449\u043e\u0442\u043e \u043d\u0435 \u0435 \u043f\u0440\u043e\u0441\u0442\u043e \u201e\u043b\u0438\u043f\u0441\u0432\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0437\u0430 \u0440\u0430\u0437\u0448\u0438\u0440\u0435\u043d\u0438\u0435\u201c. \u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435\u0442\u043e \u0441\u043e\u0447\u0438 \u043a\u043e\u043c\u0431\u0438\u043d\u0430\u0446\u0438\u044f \u043e\u0442 \u0434\u0432\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>\u041d\u0435\u043f\u0440\u0430\u0432\u0438\u043b\u043d\u043e \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0432\u0430\u043d\u0435 \u043d\u0430 \u0433\u0440\u0435\u0448\u043a\u0438 \u043f\u0440\u0438 RSA \u0434\u0435\u0448\u0438\u0444\u0440\u0438\u0440\u0430\u043d\u0435<\/strong> + <strong>\u043b\u0438\u043f\u0441\u0430 \u043d\u0430 sanitize \u043d\u0430 \u043f\u044a\u0442\u044f\/\u0438\u043c\u0435\u0442\u043e \u043f\u0440\u0438 \u0437\u0430\u043f\u0438\u0441 \u043d\u0430 \u043a\u0430\u0447\u0435\u043d\u0438\u044f \u0444\u0430\u0439\u043b<\/strong>.<\/li>\n\n\n<li>\u041f\u0440\u0438 \u043f\u0440\u043e\u0432\u0430\u043b \u043d\u0430 RSA \u0434\u0435\u0448\u0438\u0444\u0440\u0438\u0440\u0430\u043d\u0435 (\u0432 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u044f\u0442\u0430 \u0435 \u043f\u043e\u0441\u043e\u0447\u0435\u043d\u043e <code>openssl_private_decrypt()<\/code> \u043a\u0430\u0442\u043e \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442), \u043f\u043b\u044a\u0433\u0438\u043d\u044a\u0442 <strong>\u043d\u0435 \u043f\u0440\u0435\u043a\u0440\u0430\u0442\u044f\u0432\u0430 \u0438\u0437\u043f\u044a\u043b\u043d\u0435\u043d\u0438\u0435\u0442\u043e<\/strong>, \u0430 \u0432\u043c\u0435\u0441\u0442\u043e \u0442\u043e\u0432\u0430 \u043f\u043e\u0434\u0430\u0432\u0430 \u0431\u0443\u043b\u0435\u0432\u0430 \u0441\u0442\u043e\u0439\u043d\u043e\u0441\u0442 <strong><code>false<\/code><\/strong> \u043a\u044a\u043c \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0442\u0430 \u043d\u0430 AES cipher \u0432 <strong>phpseclib<\/strong>.<\/li>\n\n\n<li>\u0411\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0442\u0430 \u0442\u0440\u0435\u0442\u0438\u0440\u0430 <code>false<\/code> \u043a\u0430\u0442\u043e <strong>\u043d\u0438\u0437 \u043e\u0442 null \u0431\u0430\u0439\u0442\u043e\u0432\u0435<\/strong>, \u043a\u043e\u0435\u0442\u043e \u043f\u0440\u0430\u0432\u0438 \u043a\u043b\u044e\u0447\u0430 <strong>\u043f\u0440\u0435\u0434\u0432\u0438\u0434\u0438\u043c<\/strong> (null-byte key). \u0422\u0430\u043a\u0430 \u0430\u0442\u0430\u043a\u0443\u0432\u0430\u0449 \u043c\u043e\u0436\u0435 \u0434\u0430 \u0438\u0437\u0433\u0440\u0430\u0434\u0438 \u043a\u0440\u0438\u043f\u0442\u0438\u0440\u0430\u043d payload, \u043a\u043e\u0439\u0442\u043e \u0434\u0430 \u0431\u044a\u0434\u0435 \u0443\u0441\u043f\u0435\u0448\u043d\u043e \u201e\u0434\u0435\u0448\u0438\u0444\u0440\u0438\u0440\u0430\u043d\u201c \u0441 \u0442\u043e\u0437\u0438 \u043f\u0440\u0435\u0434\u0432\u0438\u0434\u0438\u043c \u043a\u043b\u044e\u0447.<\/li>\n\n\n<li>\u041e\u0442\u0434\u0435\u043b\u043d\u043e, \u043f\u043b\u044a\u0433\u0438\u043d\u044a\u0442 \u043f\u0440\u0438\u0435\u043c\u0430 \u0438\u043c\u0435\u043d\u0430 \u043d\u0430 \u0444\u0430\u0439\u043b\u043e\u0432\u0435 \u043e\u0442 \u0434\u0435\u0448\u0438\u0444\u0440\u0438\u0440\u0430\u043d\u0438\u044f payload <strong>\u0431\u0435\u0437 path sanitization<\/strong>, \u043a\u043e\u0435\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0432\u0430 <strong>directory traversal<\/strong> \u0438 \u0438\u0437\u043b\u0438\u0437\u0430\u043d\u0435 \u0438\u0437\u0432\u044a\u043d \u0437\u0430\u0449\u0438\u0442\u0435\u043d\u0430\u0442\u0430 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044f \u0437\u0430 \u0431\u0435\u043a\u044a\u043f\u0438.<\/li>\n\n\n<li>\u041a\u0440\u0430\u0439\u043d\u0438\u044f\u0442 \u0440\u0435\u0437\u0443\u043b\u0442\u0430\u0442: \u043d\u0435\u0430\u0432\u0442\u0435\u043d\u0442\u0438\u043a\u0438\u0440\u0430\u043d \u0430\u0442\u0430\u043a\u0443\u0432\u0430\u0449 \u043c\u043e\u0436\u0435 \u0434\u0430 \u043a\u0430\u0447\u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u0435\u043d <strong>PHP \u0444\u0430\u0439\u043b<\/strong> \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e \u0434\u043e\u0441\u0442\u044a\u043f\u043d\u0430 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044f \u0438 \u0434\u0430 \u0433\u043e \u0438\u0437\u043f\u044a\u043b\u043d\u0438, \u043a\u043e\u0435\u0442\u043e \u0432\u043e\u0434\u0438 \u0434\u043e <strong>RCE<\/strong>.<\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u041a\u044a\u0434\u0435 \u0432 \u043a\u043e\u0434\u0430 \u0441\u0435 \u0441\u043b\u0443\u0447\u0432\u0430<\/h3>\n\n\n\n<p>Wordfence \u043f\u043e\u0441\u043e\u0447\u0432\u0430\u0442, \u0447\u0435 \u043f\u0440\u0438\u0435\u043c\u0430\u043d\u0435\u0442\u043e \u043d\u0430 \u0431\u0435\u043a\u044a\u043f \u0444\u0430\u0439\u043b \u0441\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0432\u0430 \u043e\u0442 <code>send_to_site()<\/code> \u0432 \u043a\u043b\u0430\u0441\u0430 <code>WPvivid_Send_to_site<\/code>. \u0422\u0430\u043c \u0441\u0435 \u0432\u0437\u0438\u043c\u0430 <code>wpvivid_content<\/code> \u043e\u0442 <code>$_POST<\/code>, \u0434\u0435\u043a\u043e\u0434\u0438\u0440\u0430 \u0441\u0435, \u0438 \u0441\u0435 \u043f\u043e\u0434\u0430\u0432\u0430 \u043a\u044a\u043c <code>decrypt_message()<\/code> \u043e\u0442 <code>WPvivid_crypt<\/code>.<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#24292e\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#e1e4e8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>public function send_to_site()\n{\n    include_once WPVIVID_PLUGIN_DIR . '\/includes\/class-wpvivid-crypt.php';\n\n    \/\/ ...\n\n    if (isset($_POST['wpvivid_content'])) {\n        $option = get_option('wpvivid_api_token', array());\n        if (empty($option)) {\n            die();\n        }\n        if ($option['expires'] != 0 &amp;&amp; $option['expires'] &lt; time()) {\n            die();\n        }\n\n        $crypt = new WPvivid_crypt(base64_decode($option['private_key']));\n        $body  = base64_decode($_POST['wpvivid_content']);\n        $data  = $crypt-&gt;decrypt_message($body);\n\n        \/\/ ... \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0430 \u0438 \u0437\u0430\u043f\u0438\u0441 \u043d\u0430 \u0444\u0430\u0439\u043b\n    }\n}\n<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki github-dark\" style=\"background-color:#24292e;color:#e1e4e8\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color:#F97583\">public<\/span><span style=\"color:#F97583\"> function<\/span><span style=\"color:#B392F0\"> send_to_site<\/span><span style=\"color:#E1E4E8\">()<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">    include_once<\/span><span style=\"color:#79B8FF\"> WPVIVID_PLUGIN_DIR<\/span><span style=\"color:#F97583\"> .<\/span><span style=\"color:#9ECBFF\"> '\/includes\/class-wpvivid-crypt.php'<\/span><span style=\"color:#E1E4E8\">;<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#6A737D\">    \/\/ ...<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">    if<\/span><span style=\"color:#E1E4E8\"> (<\/span><span style=\"color:#79B8FF\">isset<\/span><span style=\"color:#E1E4E8\">($_POST[<\/span><span style=\"color:#9ECBFF\">'wpvivid_content'<\/span><span style=\"color:#E1E4E8\">])) {<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">        $option <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#B392F0\"> get_option<\/span><span style=\"color:#E1E4E8\">(<\/span><span style=\"color:#9ECBFF\">'wpvivid_api_token'<\/span><span style=\"color:#E1E4E8\">, <\/span><span style=\"color:#79B8FF\">array<\/span><span style=\"color:#E1E4E8\">());<\/span><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">        if<\/span><span style=\"color:#E1E4E8\"> (<\/span><span style=\"color:#79B8FF\">empty<\/span><span style=\"color:#E1E4E8\">($option)) {<\/span><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">            die<\/span><span style=\"color:#E1E4E8\">();<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">        }<\/span><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">        if<\/span><span style=\"color:#E1E4E8\"> ($option[<\/span><span style=\"color:#9ECBFF\">'expires'<\/span><span style=\"color:#E1E4E8\">] <\/span><span style=\"color:#F97583\">!=<\/span><span style=\"color:#79B8FF\"> 0<\/span><span style=\"color:#F97583\"> &#x26;&#x26;<\/span><span style=\"color:#E1E4E8\"> $option[<\/span><span style=\"color:#9ECBFF\">'expires'<\/span><span style=\"color:#E1E4E8\">] <\/span><span style=\"color:#F97583\">&#x3C;<\/span><span style=\"color:#79B8FF\"> time<\/span><span style=\"color:#E1E4E8\">()) {<\/span><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">            die<\/span><span style=\"color:#E1E4E8\">();<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">        }<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">        $crypt <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#F97583\"> new<\/span><span style=\"color:#79B8FF\"> WPvivid_crypt<\/span><span style=\"color:#E1E4E8\">(<\/span><span style=\"color:#79B8FF\">base64_decode<\/span><span style=\"color:#E1E4E8\">($option[<\/span><span style=\"color:#9ECBFF\">'private_key'<\/span><span style=\"color:#E1E4E8\">]));<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">        $body  <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> base64_decode<\/span><span style=\"color:#E1E4E8\">($_POST[<\/span><span style=\"color:#9ECBFF\">'wpvivid_content'<\/span><span style=\"color:#E1E4E8\">]);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">        $data  <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#E1E4E8\"> $crypt<\/span><span style=\"color:#F97583\">-><\/span><span style=\"color:#B392F0\">decrypt_message<\/span><span style=\"color:#E1E4E8\">($body);<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#6A737D\">        \/\/ ... \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0430 \u0438 \u0437\u0430\u043f\u0438\u0441 \u043d\u0430 \u0444\u0430\u0439\u043b<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    }<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">}<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>\u0412 <code>decrypt_message()<\/code> \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044a\u0442 \u0435, \u0447\u0435 \u043f\u0440\u0438 \u043d\u0435\u0443\u0441\u043f\u0435\u0448\u043d\u043e RSA \u0434\u0435\u0448\u0438\u0444\u0440\u0438\u0440\u0430\u043d\u0435 \u0441\u0442\u043e\u0439\u043d\u043e\u0441\u0442\u0442\u0430 <code>$key<\/code> \u043c\u043e\u0436\u0435 \u0434\u0430 \u0441\u0442\u0430\u043d\u0435 <code>false<\/code>, \u043d\u043e \u0432\u044a\u043f\u0440\u0435\u043a\u0438 \u0442\u043e\u0432\u0430 \u0441\u0435 \u043f\u043e\u043b\u0437\u0432\u0430 \u0437\u0430 \u043a\u043b\u044e\u0447 \u043d\u0430 <code>Crypt_Rijndael()<\/code>.<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#24292e\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#e1e4e8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>public function decrypt_message($message)\n{\n    $len = substr($message, 0, 3);\n    $len = hexdec($len);\n    $key = substr($message, 3, $len);\n\n    $cipherlen = substr($message, ($len + 3), 16);\n    $cipherlen = hexdec($cipherlen);\n\n    $data = substr($message, ($len + 19), $cipherlen);\n\n    $rsa = new Crypt_RSA();\n    $rsa-&gt;loadKey($this-&gt;public_key);\n    $key = $rsa-&gt;decrypt($key);\n\n    $rij = new Crypt_Rijndael();\n    $rij-&gt;setKey($key);\n\n    return $rij-&gt;decrypt($data);\n}\n<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki github-dark\" style=\"background-color:#24292e;color:#e1e4e8\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color:#F97583\">public<\/span><span style=\"color:#F97583\"> function<\/span><span style=\"color:#B392F0\"> decrypt_message<\/span><span style=\"color:#E1E4E8\">($message)<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $len <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> substr<\/span><span style=\"color:#E1E4E8\">($message, <\/span><span style=\"color:#79B8FF\">0<\/span><span style=\"color:#E1E4E8\">, <\/span><span style=\"color:#79B8FF\">3<\/span><span style=\"color:#E1E4E8\">);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $len <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> hexdec<\/span><span style=\"color:#E1E4E8\">($len);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $key <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> substr<\/span><span style=\"color:#E1E4E8\">($message, <\/span><span style=\"color:#79B8FF\">3<\/span><span style=\"color:#E1E4E8\">, $len);<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $cipherlen <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> substr<\/span><span style=\"color:#E1E4E8\">($message, ($len <\/span><span style=\"color:#F97583\">+<\/span><span style=\"color:#79B8FF\"> 3<\/span><span style=\"color:#E1E4E8\">), <\/span><span style=\"color:#79B8FF\">16<\/span><span style=\"color:#E1E4E8\">);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $cipherlen <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> hexdec<\/span><span style=\"color:#E1E4E8\">($cipherlen);<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $data <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> substr<\/span><span style=\"color:#E1E4E8\">($message, ($len <\/span><span style=\"color:#F97583\">+<\/span><span style=\"color:#79B8FF\"> 19<\/span><span style=\"color:#E1E4E8\">), $cipherlen);<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $rsa <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#F97583\"> new<\/span><span style=\"color:#79B8FF\"> Crypt_RSA<\/span><span style=\"color:#E1E4E8\">();<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $rsa<\/span><span style=\"color:#F97583\">-><\/span><span style=\"color:#B392F0\">loadKey<\/span><span style=\"color:#E1E4E8\">(<\/span><span style=\"color:#79B8FF\">$this<\/span><span style=\"color:#F97583\">-><\/span><span style=\"color:#E1E4E8\">public_key);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $key <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#E1E4E8\"> $rsa<\/span><span style=\"color:#F97583\">-><\/span><span style=\"color:#B392F0\">decrypt<\/span><span style=\"color:#E1E4E8\">($key);<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $rij <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#F97583\"> new<\/span><span style=\"color:#79B8FF\"> Crypt_Rijndael<\/span><span style=\"color:#E1E4E8\">();<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $rij<\/span><span style=\"color:#F97583\">-><\/span><span style=\"color:#B392F0\">setKey<\/span><span style=\"color:#E1E4E8\">($key);<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">    return<\/span><span style=\"color:#E1E4E8\"> $rij<\/span><span style=\"color:#F97583\">-><\/span><span style=\"color:#B392F0\">decrypt<\/span><span style=\"color:#E1E4E8\">($data);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">}<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>\u0422\u043e\u0432\u0430 \u043e\u0442\u0432\u0430\u0440\u044f \u0432\u0440\u0430\u0442\u0430\u0442\u0430 \u0437\u0430 \u043f\u0440\u0435\u0434\u0432\u0438\u0434\u0438\u043c \u201e\u043d\u0443\u043b\u0435\u0432\u201c \u043a\u043b\u044e\u0447 \u0438 \u0432\u044a\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442 \u0437\u0430 \u0437\u043b\u043e\u043d\u0430\u043c\u0435\u0440\u0435\u043d \u043a\u0440\u0438\u043f\u0442\u0438\u0440\u0430\u043d payload. \u0412 \u043a\u043e\u043c\u0431\u0438\u043d\u0430\u0446\u0438\u044f \u0441 \u043b\u0438\u043f\u0441\u0432\u0430\u0449\u0430 sanitation \u043d\u0430 \u043f\u044a\u0442\u044f\/\u0438\u043c\u0435\u0442\u043e, \u0430\u0442\u0430\u043a\u0443\u0432\u0430\u0449 \u043c\u043e\u0436\u0435 \u0434\u0430 \u0438\u0437\u0431\u044f\u0433\u0430 \u043e\u0442 backup \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044f\u0442\u0430 \u0438 \u0434\u0430 \u0437\u0430\u043f\u0438\u0448\u0435 \u0444\u0430\u0439\u043b \u0442\u0430\u043c, \u043a\u044a\u0434\u0435\u0442\u043e \u043f\u043e\u0441\u043b\u0435 \u043c\u043e\u0436\u0435 \u0434\u0430 \u0431\u044a\u0434\u0435 \u0438\u0437\u043f\u044a\u043b\u043d\u0435\u043d \u043e\u0442 PHP.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u041a\u0430\u043a\u0432\u043e \u043f\u0440\u043e\u043c\u0435\u043d\u044f \u043f\u0430\u0447\u044a\u0442 \u0432 0.9.124<\/h2>\n\n\n\n<p>\u041f\u043e \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435\u0442\u043e \u0432 Wordfence, \u0444\u0438\u043a\u0441\u043e\u0432\u0435\u0442\u0435 \u0441\u0430 \u0432 \u0434\u0432\u0435 \u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f: (1) \u0432\u0430\u043b\u0438\u0434\u0438\u0440\u0430\u043d\u0435 \u043d\u0430 \u0440\u0435\u0437\u0443\u043b\u0442\u0430\u0442\u0430 \u043e\u0442 RSA \u0434\u0435\u0448\u0438\u0444\u0440\u0438\u0440\u0430\u043d\u0435; (2) \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0430\u0432\u0430\u043d\u0435 \u043d\u0430 \u043a\u0430\u0447\u0432\u0430\u043d\u0438\u0442\u0435 \u0444\u0430\u0439\u043b\u043e\u0432\u0435 \u0434\u043e \u0442\u0438\u043f\u043e\u0432\u0435, \u0445\u0430\u0440\u0430\u043a\u0442\u0435\u0440\u043d\u0438 \u0437\u0430 \u0431\u0435\u043a\u044a\u043f.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1) Stop-\u043b\u043e\u0433\u0438\u043a\u0430 \u043f\u0440\u0438 \u043d\u0435\u0432\u0430\u043b\u0438\u0434\u0435\u043d \u043a\u043b\u044e\u0447<\/h3>\n\n\n\n<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u044a\u0442 \u0434\u043e\u0431\u0430\u0432\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0434\u0430\u043b\u0438 <code>$key<\/code> \u0435 <code>false<\/code> \u0438\u043b\u0438 \u043f\u0440\u0430\u0437\u0435\u043d \u0438 \u043f\u0440\u0435\u043a\u0440\u0430\u0442\u044f\u0432\u0430 \u043f\u0440\u043e\u0446\u0435\u0441\u0430 (\u0432\u0440\u044a\u0449\u0430 <code>false<\/code>), \u043f\u0440\u0435\u0434\u0438 \u0434\u0430 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u0430 cipher-\u0430.<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#24292e\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#e1e4e8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>$key = $rsa-&gt;decrypt($key);\nif ($key === false || empty($key))\n{\n    return false;\n}\n\n$rij = new Crypt_Rijndael();\n$rij-&gt;setKey($key);\nreturn $rij-&gt;decrypt($data);\n<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki github-dark\" style=\"background-color:#24292e;color:#e1e4e8\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color:#E1E4E8\">$key <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#E1E4E8\"> $rsa<\/span><span style=\"color:#F97583\">-><\/span><span style=\"color:#B392F0\">decrypt<\/span><span style=\"color:#E1E4E8\">($key);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">if<\/span><span style=\"color:#E1E4E8\"> ($key <\/span><span style=\"color:#F97583\">===<\/span><span style=\"color:#79B8FF\"> false<\/span><span style=\"color:#F97583\"> ||<\/span><span style=\"color:#79B8FF\"> empty<\/span><span style=\"color:#E1E4E8\">($key))<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">    return<\/span><span style=\"color:#79B8FF\"> false<\/span><span style=\"color:#E1E4E8\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">}<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">$rij <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#F97583\"> new<\/span><span style=\"color:#79B8FF\"> Crypt_Rijndael<\/span><span style=\"color:#E1E4E8\">();<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">$rij<\/span><span style=\"color:#F97583\">-><\/span><span style=\"color:#B392F0\">setKey<\/span><span style=\"color:#E1E4E8\">($key);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">return<\/span><span style=\"color:#E1E4E8\"> $rij<\/span><span style=\"color:#F97583\">-><\/span><span style=\"color:#B392F0\">decrypt<\/span><span style=\"color:#E1E4E8\">($data);<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">2) \u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043d\u0430 \u0440\u0430\u0437\u0448\u0438\u0440\u0435\u043d\u0438\u0435\u0442\u043e \u0438 sanitize \u043d\u0430 \u0438\u043c\u0435\u0442\u043e<\/h3>\n\n\n\n<p>\u0412 <code>send_to_site()<\/code> \u0435 \u0434\u043e\u0431\u0430\u0432\u0435\u043d\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043d\u0430 \u0440\u0430\u0437\u0448\u0438\u0440\u0435\u043d\u0438\u0435\u0442\u043e \u0438 \u043f\u043e-\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e \u0444\u043e\u0440\u043c\u0438\u0440\u0430\u043d\u0435 \u043d\u0430 \u0438\u043c\u0435\u0442\u043e \u0447\u0440\u0435\u0437 <code>basename()<\/code> \u0438 <code>preg_replace()<\/code>. \u041f\u043e\u0437\u0432\u043e\u043b\u0435\u043d\u0438 \u0441\u0430 \u0441\u0430\u043c\u043e \u0440\u0430\u0437\u0448\u0438\u0440\u0435\u043d\u0438\u044f, \u0442\u0438\u043f\u0438\u0447\u043d\u0438 \u0437\u0430 \u0431\u0435\u043a\u044a\u043f\/\u0430\u0440\u0445\u0438\u0432\u0438: <code>zip<\/code>, <code>gz<\/code>, <code>tar<\/code>, <code>sql<\/code>.<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#24292e\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#e1e4e8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>$safe_name = basename($params['name']);\n$safe_name = preg_replace('\/[^a-zA-Z0-9._-]\/', '', $safe_name);\n\n$allowed_extensions = array('zip', 'gz', 'tar', 'sql');\n$file_ext = strtolower(pathinfo($safe_name, PATHINFO_EXTENSION));\n\nif (!in_array($file_ext, $allowed_extensions, true))\n{\n    $ret['result'] = WPVIVID_FAILED;\n    $ret['error']  = 'Invalid file type - only backup files allowed.';\n    echo wp_json_encode($ret);\n    die();\n}\n<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki github-dark\" style=\"background-color:#24292e;color:#e1e4e8\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color:#E1E4E8\">$safe_name <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> basename<\/span><span style=\"color:#E1E4E8\">($params[<\/span><span style=\"color:#9ECBFF\">'name'<\/span><span style=\"color:#E1E4E8\">]);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">$safe_name <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> preg_replace<\/span><span style=\"color:#E1E4E8\">(<\/span><span style=\"color:#9ECBFF\">'\/<\/span><span style=\"color:#DBEDFF\">[^a-zA-Z0-9._-]<\/span><span style=\"color:#9ECBFF\">\/'<\/span><span style=\"color:#E1E4E8\">, <\/span><span style=\"color:#9ECBFF\">''<\/span><span style=\"color:#E1E4E8\">, $safe_name);<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">$allowed_extensions <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> array<\/span><span style=\"color:#E1E4E8\">(<\/span><span style=\"color:#9ECBFF\">'zip'<\/span><span style=\"color:#E1E4E8\">, <\/span><span style=\"color:#9ECBFF\">'gz'<\/span><span style=\"color:#E1E4E8\">, <\/span><span style=\"color:#9ECBFF\">'tar'<\/span><span style=\"color:#E1E4E8\">, <\/span><span style=\"color:#9ECBFF\">'sql'<\/span><span style=\"color:#E1E4E8\">);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">$file_ext <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> strtolower<\/span><span style=\"color:#E1E4E8\">(<\/span><span style=\"color:#79B8FF\">pathinfo<\/span><span style=\"color:#E1E4E8\">($safe_name, <\/span><span style=\"color:#79B8FF\">PATHINFO_EXTENSION<\/span><span style=\"color:#E1E4E8\">));<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">if<\/span><span style=\"color:#E1E4E8\"> (<\/span><span style=\"color:#F97583\">!<\/span><span style=\"color:#79B8FF\">in_array<\/span><span style=\"color:#E1E4E8\">($file_ext, $allowed_extensions, <\/span><span style=\"color:#79B8FF\">true<\/span><span style=\"color:#E1E4E8\">))<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $ret[<\/span><span style=\"color:#9ECBFF\">'result'<\/span><span style=\"color:#E1E4E8\">] <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#79B8FF\"> WPVIVID_FAILED<\/span><span style=\"color:#E1E4E8\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">    $ret[<\/span><span style=\"color:#9ECBFF\">'error'<\/span><span style=\"color:#E1E4E8\">]  <\/span><span style=\"color:#F97583\">=<\/span><span style=\"color:#9ECBFF\"> 'Invalid file type - only backup files allowed.'<\/span><span style=\"color:#E1E4E8\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color:#79B8FF\">    echo<\/span><span style=\"color:#B392F0\"> wp_json_encode<\/span><span style=\"color:#E1E4E8\">($ret);<\/span><\/span>\n<span class=\"line\"><span style=\"color:#F97583\">    die<\/span><span style=\"color:#E1E4E8\">();<\/span><\/span>\n<span class=\"line\"><span style=\"color:#E1E4E8\">}<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">\u041a\u0430\u043a \u0434\u0430 \u0441\u0435 \u0437\u0430\u0449\u0438\u0442\u0438\u0448 (\u0447\u0435\u043a\u043b\u0438\u0441\u0442 \u0437\u0430 \u0430\u0434\u043c\u0438\u043d\u0438 \u0438 \u0434\u0435\u0432 \u0435\u043a\u0438\u043f\u0438)<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li><strong>\u041e\u0431\u043d\u043e\u0432\u0438 WPvivid Backup \u0434\u043e 0.9.124<\/strong> (\u0438\u043b\u0438 \u043f\u043e-\u043d\u043e\u0432\u0430, \u0430\u043a\u043e \u0432\u0435\u0447\u0435 \u0438\u043c\u0430). \u0422\u043e\u0432\u0430 \u0435 \u043a\u043b\u044e\u0447\u043e\u0432\u043e\u0442\u043e \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435, \u0437\u0430\u0449\u043e\u0442\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0442\u0430 \u0435 \u043d\u0430\u043f\u044a\u043b\u043d\u043e \u0430\u0434\u0440\u0435\u0441\u0438\u0440\u0430\u043d\u0430 \u0432 0.9.124 \u0441\u043f\u043e\u0440\u0435\u0434 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u044f\u0442\u0430.<\/li>\n\n\n<li><strong>\u041f\u0440\u043e\u0432\u0435\u0440\u0438 \u0434\u0430\u043b\u0438 \u0435 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0430\u043d \u043a\u043b\u044e\u0447<\/strong> \u0437\u0430 \u201ereceive backup from another site\u201c \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u043d\u043e\u0441\u0442\u0442\u0430. \u0410\u043a\u043e \u0442\u043e\u0437\u0438 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u0439 \u043d\u0435 \u0442\u0438 \u0442\u0440\u044f\u0431\u0432\u0430, \u043d\u0435 \u0433\u043e \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u0430\u0439.<\/li>\n\n\n<li>\u0410\u043a\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u043d\u043e\u0441\u0442\u0442\u0430 \u0442\u0438 \u0442\u0440\u044f\u0431\u0432\u0430: <strong>\u0434\u0440\u044a\u0436 \u043a\u043b\u044e\u0447\u043e\u0432\u0435\u0442\u0435 \u043a\u0440\u0430\u0442\u043a\u043e\u0441\u0440\u043e\u0447\u043d\u0438<\/strong>. \u041f\u043b\u044a\u0433\u0438\u043d\u044a\u0442 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0432\u0430 expiration \u043c\u0430\u043a\u0441\u0438\u043c\u0443\u043c <strong>24 \u0447\u0430\u0441\u0430<\/strong> &#8211; \u0438\u0437\u043f\u043e\u043b\u0437\u0432\u0430\u0439 \u0433\u043e \u043f\u043e \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u0438 \u043d\u0435 \u043e\u0441\u0442\u0430\u0432\u044f\u0439 \u043a\u043b\u044e\u0447\u043e\u0432\u0435 \u0430\u043a\u0442\u0438\u0432\u043d\u0438 \u0431\u0435\u0437 \u043d\u0443\u0436\u0434\u0430.<\/li>\n\n\n<li>\u0410\u043a\u043e \u043f\u043e\u043b\u0437\u0432\u0430\u0448 Wordfence: \u0438\u043c\u0430\u0439 \u043f\u0440\u0435\u0434\u0432\u0438\u0434, \u0447\u0435 <strong>Wordfence Premium\/Care\/Response<\/strong> \u0441\u0430 \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0438 firewall \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u043d\u0430 <strong>January 22, 2026<\/strong>, \u0430 <strong>Wordfence Free<\/strong> \u043f\u043e\u043b\u0443\u0447\u0430\u0432\u0430 \u0441\u044a\u0449\u0430\u0442\u0430 \u0437\u0430\u0449\u0438\u0442\u0430 <strong>30 \u0434\u043d\u0438 \u043f\u043e-\u043a\u044a\u0441\u043d\u043e &#8211; February 21, 2026<\/strong>.<\/li>\n\n\n<li>\u041f\u0440\u0435\u0433\u043b\u0435\u0434\u0430\u0439 \u0444\u0430\u0439\u043b\u043e\u0432\u0430\u0442\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0430 \u0437\u0430 \u043d\u0435\u043e\u0447\u0430\u043a\u0432\u0430\u043d\u0438 PHP \u0444\u0430\u0439\u043b\u043e\u0432\u0435 \u0432 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u0438, \u043a\u043e\u0438\u0442\u043e \u0441\u0430 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e \u0434\u043e\u0441\u0442\u044a\u043f\u043d\u0438 (\u0442\u0438\u043f\u0438\u0447\u0435\u043d \u043f\u0440\u0438\u0437\u043d\u0430\u043a \u043f\u0440\u0438 arbitrary upload \u2192 webshell). \u0422\u043e\u0432\u0430 \u0435 \u043e\u0441\u043e\u0431\u0435\u043d\u043e \u0432\u0430\u0436\u043d\u043e, \u0430\u043a\u043e \u0437\u043d\u0430\u0435\u0448, \u0447\u0435 \u0435 \u0438\u043c\u0430\u043b\u043e \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u0430\u043d \u043a\u043b\u044e\u0447 \u0432 \u0440\u0438\u0441\u043a\u043e\u0432\u0438\u044f \u043f\u0435\u0440\u0438\u043e\u0434.<\/li>\n\n\n<li>\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0438\u0440\u0430\u0439 \u0449\u0435\u0442\u0438\u0442\u0435 \u043f\u0440\u0438 \u043f\u0440\u043e\u0431\u0438\u0432: \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438 write \u043f\u0440\u0430\u0432\u0430 \u0442\u0430\u043c, \u043a\u044a\u0434\u0435\u0442\u043e \u043d\u0435 \u0441\u0430 \u043d\u0443\u0436\u043d\u0438, \u0438 \u0441\u043b\u0435\u0434\u0438 \u0437\u0430 \u043f\u0440\u043e\u043c\u0435\u043d\u0438 \u043f\u043e \u0444\u0430\u0439\u043b\u043e\u0432\u0435\u0442\u0435 (file integrity monitoring).<\/li>\n\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">\u0414\u0435\u0442\u0430\u0439\u043b\u0438 \u043e\u0442 disclosure \u043f\u0440\u043e\u0446\u0435\u0441\u0430 (\u0445\u0440\u043e\u043d\u043e\u043b\u043e\u0433\u0438\u044f)<\/h2>\n\n\n\n<p>Wordfence \u043f\u0443\u0431\u043b\u0438\u043a\u0443\u0432\u0430\u0442 \u0438 \u044f\u0441\u043d\u0430 timeline \u043d\u0430 disclosure-\u0430, \u043a\u043e\u044f\u0442\u043e \u0435 \u043f\u043e\u043b\u0435\u0437\u043d\u0430 \u0437\u0430 \u043e\u0446\u0435\u043d\u043a\u0430 \u043d\u0430 \u0440\u0438\u0441\u043a\u0430 \u0438 \u043f\u0440\u043e\u0437\u043e\u0440\u0435\u0446\u0430 \u0437\u0430 \u0435\u043a\u0441\u043f\u043b\u043e\u0430\u0442\u0430\u0446\u0438\u044f:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>January 12, 2026<\/strong> &#8211; \u043f\u043e\u0434\u0430\u0434\u0435\u043d \u0435 \u0440\u0435\u043f\u043e\u0440\u0442 \u0437\u0430 Arbitrary File Upload \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0442\u0430 \u0447\u0440\u0435\u0437 Wordfence Bug Bounty Program.<\/li>\n\n\n<li><strong>January 22, 2026<\/strong> &#8211; Wordfence \u0432\u0430\u043b\u0438\u0434\u0438\u0440\u0430\u0442 \u0440\u0435\u043f\u043e\u0440\u0442\u0430 \u0438 \u043f\u043e\u0442\u0432\u044a\u0440\u0436\u0434\u0430\u0432\u0430\u0442 proof-of-concept \u0435\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430. \u0418\u0437\u043f\u0440\u0430\u0449\u0430\u0442 \u043f\u044a\u0440\u0432\u043e\u043d\u0430\u0447\u0430\u043b\u0435\u043d \u043a\u043e\u043d\u0442\u0430\u043a\u0442 \u043a\u044a\u043c \u0434\u043e\u0441\u0442\u0430\u0432\u0447\u0438\u043a\u0430 \u0438 \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0442 \u0438\u0437\u043f\u043e\u043b\u0437\u0432\u0430\u043d\u0435 \u043d\u0430 <a href=\"https:\/\/www.wordfence.com\/threat-intel\/vendor\/vulnerability-management-portal\/\">Wordfence Vulnerability Management Portal<\/a>.<\/li>\n\n\n<li><strong>January 22, 2026<\/strong> &#8211; \u043f\u043e\u0442\u0440\u0435\u0431\u0438\u0442\u0435\u043b\u0438\u0442\u0435 \u043d\u0430 <a href=\"https:\/\/www.wordfence.com\/products\/wordfence-premium\/\">Wordfence Premium<\/a>, <a href=\"https:\/\/www.wordfence.com\/products\/wordfence-care\/\">Wordfence Care<\/a> \u0438 <a href=\"https:\/\/www.wordfence.com\/products\/wordfence-response\/\">Wordfence Response<\/a> \u043f\u043e\u043b\u0443\u0447\u0430\u0432\u0430\u0442 firewall \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0437\u0430 \u0434\u043e\u043f\u044a\u043b\u043d\u0438\u0442\u0435\u043b\u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0430.<\/li>\n\n\n<li><strong>January 23, 2026<\/strong> &#8211; \u0434\u043e\u0441\u0442\u0430\u0432\u0447\u0438\u043a\u044a\u0442 \u043e\u0442\u0433\u043e\u0432\u0430\u0440\u044f \u0438 \u0438\u0437\u0431\u0438\u0440\u0430 \u043a\u043e\u043c\u0443\u043d\u0438\u043a\u0430\u0446\u0438\u044f \u043f\u043e email.<\/li>\n\n\n<li><strong>January 23, 2026<\/strong> &#8211; Wordfence \u0438\u0437\u043f\u0440\u0430\u0449\u0430\u0442 \u043f\u044a\u043b\u043d\u0438\u0442\u0435 \u0434\u0435\u0442\u0430\u0439\u043b\u0438 \u043f\u043e disclosure-\u0430; \u0434\u043e\u0441\u0442\u0430\u0432\u0447\u0438\u043a\u044a\u0442 \u043f\u043e\u0442\u0432\u044a\u0440\u0436\u0434\u0430\u0432\u0430 \u0438 \u0437\u0430\u043f\u043e\u0447\u0432\u0430 \u0440\u0430\u0431\u043e\u0442\u0430 \u043f\u043e fix.<\/li>\n\n\n<li><strong>January 28, 2026<\/strong> &#8211; \u0438\u0437\u043b\u0438\u0437\u0430 \u043d\u0430\u043f\u044a\u043b\u043d\u043e \u043f\u043e\u043f\u0440\u0430\u0432\u0435\u043d\u0430\u0442\u0430 \u0432\u0435\u0440\u0441\u0438\u044f <strong>0.9.124<\/strong>.<\/li>\n\n\n<li><strong>February 21, 2026<\/strong> &#8211; \u043f\u043e\u0442\u0440\u0435\u0431\u0438\u0442\u0435\u043b\u0438\u0442\u0435 \u043d\u0430 Wordfence Free \u043f\u043e\u043b\u0443\u0447\u0430\u0432\u0430\u0442 \u0441\u044a\u0449\u043e\u0442\u043e firewall \u043f\u0440\u0430\u0432\u0438\u043b\u043e.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u041a\u0440\u0435\u0434\u0438\u0442 \u043a\u044a\u043c \u043e\u0442\u043a\u0440\u0438\u0432\u0430\u0442\u0435\u043b\u044f \u0438 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442 \u0437\u0430 Bug Bounty<\/h2>\n\n\n\n<p>\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0442\u0430 \u0435 \u043e\u0442\u043a\u0440\u0438\u0442\u0430 \u0438 \u0434\u043e\u043a\u043b\u0430\u0434\u0432\u0430\u043d\u0430 \u043e\u0442 <strong>Lucas Montes (NiRoX)<\/strong> \u0447\u0440\u0435\u0437 Wordfence <strong>Bug Bounty Program<\/strong>. \u041f\u043e \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u044f\u0442\u0430 \u0440\u0435\u043f\u043e\u0440\u0442\u044a\u0442 \u0435 \u043f\u043e\u0441\u0442\u044a\u043f\u0438\u043b <strong>\u0441\u0430\u043c\u043e 5 \u0434\u043d\u0438 \u0441\u043b\u0435\u0434 \u0432\u044a\u0432\u0435\u0436\u0434\u0430\u043d\u0435\u0442\u043e<\/strong> \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0442\u0430, \u0430 \u0438\u0437\u043f\u043b\u0430\u0442\u0435\u043d\u0430\u0442\u0430 \u043d\u0430\u0433\u0440\u0430\u0434\u0430 \u0435 <strong>$2,145.00<\/strong>.<\/p>\n\n\n\n<p>\u0422\u0435\u0437\u0438 \u0434\u0435\u0442\u0430\u0439\u043b\u0438 \u0441\u0430 \u043f\u043e\u043b\u0435\u0437\u043d\u0438, \u0437\u0430\u0449\u043e\u0442\u043e \u043f\u043e\u043a\u0430\u0437\u0432\u0430\u0442 \u043a\u043e\u043b\u043a\u043e \u0431\u044a\u0440\u0437\u043e \u043c\u043e\u0436\u0435 \u0434\u0430 \u0441\u0435 \u043f\u043e\u044f\u0432\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u043d \u0434\u0435\u0444\u0435\u043a\u0442 \u0438 \u043a\u043e\u043b\u043a\u043e \u0432\u0430\u0436\u043d\u0438 \u0441\u0430 \u043f\u0440\u043e\u0446\u0435\u0441\u0438\u0442\u0435 \u043f\u043e disclosure \u0438 \u0440\u0435\u0430\u043a\u0446\u0438\u044f \u043e\u0442 \u0441\u0442\u0440\u0430\u043d\u0430 \u043d\u0430 \u0434\u043e\u0441\u0442\u0430\u0432\u0447\u0438\u043a\u0430. \u0412 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u0438\u044f \u0441\u043b\u0443\u0447\u0430\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u0446\u0438\u0442\u0435 \u043d\u0430 WPvivid \u043f\u0443\u0441\u043a\u0430\u0442 \u043f\u0430\u0447 \u0441\u0440\u0430\u0432\u043d\u0438\u0442\u0435\u043b\u043d\u043e \u0431\u044a\u0440\u0437\u043e \u0438 Wordfence \u0433\u0438 \u043e\u0442\u0431\u0435\u043b\u044f\u0437\u0432\u0430\u0442 \u0437\u0430 \u043d\u0430\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u0430 \u0438 \u043f\u0440\u043e\u0437\u0440\u0430\u0447\u043d\u0430 \u0440\u0435\u0430\u043a\u0446\u0438\u044f.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u0417\u0430\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435<\/h2>\n\n\n\n<p>CVE-2026-1357 \u0435 \u043a\u0440\u0438\u0442\u0438\u0447\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442 \u0432 WPvivid Backup &#038; Migration (\u0432\u0435\u0440\u0441\u0438\u0438 <strong>0.9.123 \u0438 \u043f\u043e-\u0441\u0442\u0430\u0440\u0438<\/strong>), \u043a\u043e\u044f\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0432\u0430 <strong>\u043d\u0435\u0430\u0432\u0442\u0435\u043d\u0442\u0438\u043a\u0438\u0440\u0430\u043d\u043e \u043a\u0430\u0447\u0432\u0430\u043d\u0435 \u043d\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u043d\u0438 \u0444\u0430\u0439\u043b\u043e\u0432\u0435<\/strong> \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u043d\u043e <strong>RCE<\/strong>, \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u0435\u043b\u043d\u043e \u0447\u0440\u0435\u0437 webshell \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u0438. \u0424\u0438\u043a\u0441\u044a\u0442 \u0435 \u043d\u0430\u043b\u0438\u0447\u0435\u043d \u0432 <strong>0.9.124<\/strong> \u0438 \u0432\u043a\u043b\u044e\u0447\u0432\u0430 \u043a\u0430\u043a\u0442\u043e \u043f\u0440\u0430\u0432\u0438\u043b\u043d\u043e \u043f\u0440\u0435\u043a\u0440\u0430\u0442\u044f\u0432\u0430\u043d\u0435 \u043f\u0440\u0438 \u043d\u0435\u0432\u0430\u043b\u0438\u0434\u0435\u043d \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0441\u043a\u0438 \u043a\u043b\u044e\u0447, \u0442\u0430\u043a\u0430 \u0438 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0432\u044a\u0440\u0445\u0443 \u0442\u0438\u043f\u043e\u0432\u0435\u0442\u0435 \u0444\u0430\u0439\u043b\u043e\u0432\u0435, \u043a\u043e\u0438\u0442\u043e \u043c\u043e\u0433\u0430\u0442 \u0434\u0430 \u0431\u044a\u0434\u0430\u0442 \u043a\u0430\u0447\u0432\u0430\u043d\u0438 \u043f\u0440\u0435\u0437 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u043d\u043e\u0441\u0442\u0442\u0430 \u0437\u0430 receiving backups.<\/p>\n\n\n<div class=\"references-section\">\n                <h2>\u041f\u0440\u0435\u043f\u0440\u0430\u0442\u043a\u0438 \/ \u0418\u0437\u0442\u043e\u0447\u043d\u0438\u0446\u0438<\/h2>\n                <ul class=\"references-list\"><li><a href=\"https:\/\/www.wordfence.com\/blog\/2026\/02\/800000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-wpvivid-backup-wordpress-plugin\/\" target=\"_blank\" rel=\"noopener noreferrer\">800,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in WPvivid Backup WordPress Plugin<\/a><\/li><li><a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpvivid-backuprestore\/migration-backup-staging-09123-unauthenticated-arbitrary-file-upload\" target=\"_blank\" rel=\"noopener noreferrer\">Migration, Backup, Staging &lt;= 0.9.123 &#8212; Unauthenticated Arbitrary File Upload<\/a><\/li><li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1357\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2026-1357<\/a><\/li><li><a href=\"https:\/\/wordpress.org\/plugins\/wpvivid-backuprestore\/\" target=\"_blank\" rel=\"noopener noreferrer\">WPvivid Backup &amp; Migration (WordPress.org plugin page)<\/a><\/li><li><a href=\"https:\/\/www.wordfence.com\/threat-intel\/bug-bounty-program\/\" target=\"_blank\" rel=\"noopener noreferrer\">Wordfence Bug Bounty Program<\/a><\/li><\/ul>\n            <\/div>","protected":false},"excerpt":{"rendered":"<p>\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442 \u0441 CVSS 9.8 \u0432 WPvivid Backup \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0432\u0430 \u043d\u0430 \u043d\u0435\u0430\u0432\u0442\u0435\u043d\u0442\u0438\u043a\u0438\u0440\u0430\u043d\u0438 \u0430\u0442\u0430\u043a\u0443\u0432\u0430\u0449\u0438 \u0434\u0430 \u043a\u0430\u0447\u0432\u0430\u0442 \u0444\u0430\u0439\u043b\u043e\u0432\u0435 \u0438 \u0434\u0430 \u0441\u0442\u0438\u0433\u043d\u0430\u0442 \u0434\u043e remote code execution &#8211; \u043d\u043e \u0441\u0430\u043c\u043e \u0430\u043a\u043e \u0435 \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u0430\u043d\u0430 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u0441 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0430\u043d \u043a\u043b\u044e\u0447.<\/p>\n","protected":false},"author":39,"featured_media":198,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[114,13,9,113,115],"class_list":["post-199","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-50","tag-cve-2026-1357","tag-wordfence","tag-wordpress","tag-wpvivid-backup","tag-115"],"_links":{"self":[{"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/posts\/199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/comments?post=199"}],"version-history":[{"count":0,"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/posts\/199\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/media\/198"}],"wp:attachment":[{"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/media?parent=199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/categories?post=199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/helloblog.io\/bg\/wp-json\/wp\/v2\/tags?post=199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}